To simplify the process of creating roles and assigning permissions, there are preconfigured roles in NetWitness Platform.

Role

Permission

Administrators

Full system access. The System Administrators persona is granted all permissions by default.

Respond_Administrator

Access to all Respond permissions. The Respond Administrator persona is focused on system configuration of Respond.

Data_Privacy_Officers

The Data Privacy Officer (DPO) persona is similar to Administrators with additional focus on configuration options that manage obfuscation and viewing of sensitive data within the system (see the Data Privacy Management Guide). Users with the DPO role can see which meta keys are flagged for obfuscation, and they also see obfuscated meta keys and values created for the flagged meta keys.

SOC_Managers

Same access as Analysts plus additional permission to handle incidents. The SOC Managers persona is identical to Analysts, but with permissions necessary to configure Respond.

Operators

Access to configurations but not to meta and session content. The System Operators persona is focused on system configuration, but not investigation, ESA, Alerting, Reporting, and Respond.

Malware_Analysts

Access to investigations and malware events. The only access granted to the Malware Analysts persona is the Malware Analysis module.

Analysts

Access to meta and session content but not to configurations. The Security Operation Center (SOC) Analysts persona is centered around investigation, ESA Alerting, Reporting, and Respond, but not system configuration.

UEBA_Analysts

Access to the RSA NetWitness UEBA service in the Investigate > Users view. NetWitness UEBA is an advanced analytics solution for discovering, investigating, and monitoring risky behaviors across all entities in your network environment.

Note: You do not need to set up specific permissions for this role. You only need to assign this role to a user, and that user will have access to NetWitness UEBA.